Back to skill

Security audit

SumUp

Security checks for vulnerabilities and agentic risk

Overview

This SumUp skill is a disclosed single-service connector with financial write/delete capability that is scoped through the oo CLI and includes confirmation requirements for state-changing actions.

Install only if you intend to let your agent operate your SumUp account through OOMOL. Review payloads carefully before approving write or destructive actions, especially checkout creation, customer updates, and checkout deactivation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The instruction to use this skill for ANY SumUp request creates an overly broad trigger that can cause the agent to route all SumUp-related tasks through a powerful connector without sufficient narrowing by task type or risk. In a financial service context, this increases the chance of accidental invocation of read, write, or destructive actions when a more constrained workflow or explicit user confirmation policy should apply.

Static analysis

No suspicious patterns detected.